Jason Edwards
Certified: The ISC(2) ISSEP Audio Course
Certified: The ISC(2) ISSEP Certification Audio Course is built for security professionals who already speak the language of systems and risk, and now need to prove they can design security into real architectures. If you’re a practitioner moving toward security engineering, an architect who wants stronger security judgment, or a leader who has to validate designs before they ship, this course is for you. It assumes you’ve seen enterprise environments, you understand core security concepts, and you’re ready to connect them to architecture decisions that actually hold up under pressure. In Cert...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 29 — Identify Threats, Events, Vulnerabilities, and Impacts With Engineering Precision 22.02.2026 13:26
This episode teaches a precise way to identify threats, events, vulnerabilities, and impacts so your risk analysis is actionable and your exam answers stay grounded in lifecycle reality. We define each term clearly and explain the relationships, including how a threat source and threat event differ, how vulnerabilities create conditions for exploitation, and how impacts should be expressed as oper...
Episode 28 — Establish Risk Context for Systems: scope, assumptions, and decision criteria 22.02.2026 13:12
This episode focuses on establishing risk context, because without clear scope, assumptions, and decision criteria, risk analysis becomes inconsistent and ISSEP questions often test whether you can recognize that foundational gap. We define scope as what the system includes, what interfaces matter, and what environments and users are in play, then explain how assumptions shape everything from thre...
Episode 27 — Integrate Risk Management Throughout the Lifecycle From Concept to Disposal 22.02.2026 14:10
This episode teaches risk management as a continuous lifecycle activity, not a one-time assessment, which matches ISSEP’s emphasis on traceability, change control, and assurance over time. We walk through how risk decisions evolve from early concept and requirements, through design and implementation, into operations, and finally into disposal where data handling and decommissioning risks can be o...
Episode 26 — Align Security Risk Management With Enterprise Risk Management Without Translation Loss 22.02.2026 14:23
This episode explains how to align security risk work with enterprise risk management so security decisions can compete fairly with other business risks, which is a common ISSEP angle when questions test governance, accountability, and decision framing. We define where security risk management fits within ERM, including risk appetite, risk tolerance, treatment options, and escalation paths, then s...
Episode 25 — Use Monte Carlo, MTBF, MTTF, MTTR, and MTD to Explain Risk Clearly 22.02.2026 14:14
This episode connects reliability and time-based measures to security risk communication, which matters for ISSEP because the exam expects you to explain operational impact in terms leaders and engineers can act on. We define MTBF, MTTF, MTTR, and MTD in plain language, then show how they relate to availability, resiliency, and recovery objectives when systems face failures, attacks, or cascading...
Episode 24 — Estimate Cost, Personnel, and Reliability Impacts Without Fantasy Numbers 22.02.2026 13:52
This episode teaches how to estimate security impacts with realism, because ISSEP scenarios often require you to weigh controls against cost, staffing, and reliability constraints while still meeting mission needs. We cover what should be included in “cost” beyond purchase price, such as integration, operations, monitoring, incident handling, training, and lifecycle maintenance, and we explain how...
Episode 23 — Apply Supply Chain Risk Management and Review Contract Deliverables Like an Engineer 22.02.2026 14:37
This episode explains supply chain risk management as a practical set of controls and verification activities, not a checklist exercise, which aligns with the ISSEP exam’s emphasis on defensible assurance and lifecycle accountability. We define supply chain risk in terms of dependency trust, integrity of components, provenance, update pathways, and operational reliance, then show how to evaluate t...
Episode 22 — Define Security Requirements for Acquisitions That Vendors Can Actually Meet 22.02.2026 13:22
This episode focuses on writing acquisition-focused security requirements that are measurable, testable, and contract-ready, because ISSEP questions often test whether you can turn security intent into language that vendors can implement and you can verify. We define the difference between goals, requirements, and constraints, then show how to express security needs as outcomes and evidence, not b...
Episode 21 — Evaluate Security Process Automation Solutions Without Automating Bad Decisions 22.02.2026 13:30
This episode teaches how to evaluate security automation with an engineering mindset so you improve outcomes instead of scaling mistakes, which is a common ISSEP exam theme when questions test lifecycle discipline and assurance. We define what “process automation” means in security contexts, from ticket routing and evidence collection to policy enforcement and response workflows, and we explain ho...
Episode 20 — Run Information Management and Measurement Processes That Reveal Security Reality 22.02.2026 19:21
This episode focuses on information management and measurement as the way security engineering stays honest over time, because without meaningful metrics and evidence flows, you can’t defend decisions or detect when controls stop working, and ISSEP exam scenarios often test this maturity. We define what good security measurement looks like by separating activity metrics from outcome metrics, and b...
Episode 19 — Operationalize Configuration Management and Quality Assurance for Secure Systems 22.02.2026 17:23
This episode covers configuration management and quality assurance as security-critical processes that prevent drift, reduce surprise behavior, and protect the integrity of engineered controls, which is why ISSEP tests them as foundational lifecycle practices. We define configuration items, baselines, version control, change control, and auditability, then show how they support secure defaults, co...
Episode 18 — Participate in Project Management Processes Without Losing Security Intent 22.02.2026 20:57
This episode shows how security engineers stay effective inside project management realities like schedules, scope changes, resource constraints, and stakeholder communications, which the ISSEP exam often frames as scenario constraints you must respect. We define key project management concepts that affect security outcomes, including milestones, critical paths, change control, risk registers, acc...
Episode 17 — Use SDLC and Model-Based Systems Engineering to Keep Security Traceable 22.02.2026 20:04
This episode explains how SDLC practices and model-based systems engineering support traceability, consistency, and repeatable security decisions, which aligns directly with ISSEP’s emphasis on lifecycle discipline and defensible engineering outcomes. We define traceability as the ability to connect stakeholder needs to security requirements, to design elements, to verification evidence, and back...
Episode 16 — Select Assurance Methods Across Software, Hardware, Virtual, and Cloud Systems 22.02.2026 18:25
This episode walks through assurance as the confidence you can justify, based on evidence, that security objectives are met across different technology types, which matters on the ISSEP exam because it tests your ability to pick the right assurance method for the system you actually have. We define assurance methods such as reviews, testing, formal analysis, third-party assessments, and continuous...
Episode 15 — Verify Security Requirements Continuously Across SDLC and Modern Delivery 22.02.2026 19:41
This episode explains how security verification should be continuous and intentional, not a one-time event at the end of a project, and it connects verification discipline directly to exam questions that test evidence, validation logic, and lifecycle accountability. We define verification as proving requirements are met through tests, inspections, analysis, and demonstrations, and we clarify how v...
Episode 14 — Integrate Security Tasks and Activities Into Any Development Methodology 22.02.2026 22:09
This episode teaches how to embed security engineering into different delivery models, from traditional waterfall lifecycles to Agile and hybrid approaches, because the ISSEP exam cares about lifecycle fit and repeatability, not a single “correct” methodology. We define what it means to integrate security tasks as planned, measurable activities that produce artifacts, decisions, and evidence at th...
Episode 13 — Engineer Governance and Compliance Into Systems Without Killing Delivery 22.02.2026 17:44
This episode shows how to design governance and compliance as part of the system lifecycle so teams can move fast without creating unmanaged risk, a key theme in ISSEP because it tests whether you can build durable security into real delivery constraints. We define governance as decision rights and oversight mechanisms, and compliance as demonstrating adherence to requirements, then explain how bo...
Episode 12 — Work With Organizational Security Authorities to Drive Accountable Decisions 22.02.2026 18:08
This episode focuses on how security engineering succeeds inside real governance structures, where multiple authorities influence risk decisions, approvals, and accountability, and the exam often tests your ability to work within those boundaries rather than “go around them.” We clarify common authority roles you may encounter, such as system owners, authorizing officials, risk executives, securit...
Episode 11 — Choose Open, Proprietary, and Modular Design Concepts for Secure Outcomes 22.02.2026 19:47
This episode explains how architectural choices like open versus proprietary approaches and modular versus tightly coupled designs change your security posture, your assurance options, and your long-term maintainability, which is exactly the kind of tradeoff thinking the ISSEP exam expects. We define what “open” and “proprietary” really mean in practice, including visibility into internals, suppor...
Episode 10 — Execute Security Engineering Across Hardware, Software, and Data Lifecycles 22.02.2026 14:48
This episode explains how security engineering changes as you move across hardware, software, and data lifecycles, and why treating them as one generic “system lifecycle” creates blind spots. We cover what it means to define security requirements that apply to physical components, firmware, operating environments, applications, and data handling, and how assurance methods differ depending on what...
Episode 9 — Translate NIST and ISO 27001 Thinking into Practical Engineering Decisions 22.02.2026 13:05
This episode bridges the gap between framework language and engineering action, so you can move from “we should” statements to system decisions that can be implemented and verified. We discuss how NIST-style thinking and ISO 27001 concepts influence governance, risk treatment, control selection, evidence, and continuous improvement, without turning the exam into a memorization contest. You’ll lear...
Episode 8 — Use Structural Security Design Principles to Prevent Predictable Failure Modes 22.02.2026 14:51
This episode focuses on structural design principles that reduce predictable security failures before you get to control lists or tooling choices. We define principles like least privilege, separation of duties, fail-safe defaults, complete mediation, and economy of mechanism, and we connect each one to the kinds of incidents it helps prevent. You’ll hear how these principles show up in system arc...
Episode 7 — Connect Systems Engineering and Security Engineering Processes Without Gaps 22.02.2026 14:15
This episode explains how security engineering should integrate into systems engineering so security requirements, design choices, and verification evidence stay connected from concept through disposal. We cover where security fits into requirements analysis, architecture trade studies, design reviews, implementation guidance, and operational feedback loops, and why “bolt-on security” usually fail...
Episode 6 — Apply Trust Concepts and Hierarchies to Real System Security Boundaries 22.02.2026 14:18
This episode teaches trust as an engineering property you deliberately assign and continuously verify, not a vibe you assume because a component is “internal.” We define trust boundaries, trusted computing base concepts, and trust hierarchies, then show how they shape authentication, authorization, data handling, and segmentation decisions. You’ll learn how to identify where implicit trust creeps...
Episode 5 — Essential Terms: Plain-Language Glossary for Fast Security Engineering Recall 22.02.2026 14:58
This episode builds a plain-language glossary of security engineering terms that ISSEP expects you to use precisely, especially when questions hinge on small wording differences. We define core ideas like requirement, constraint, assumption, baseline, traceability, assurance, verification, validation, and acceptance criteria, then explain how each term changes what you do in a real project. You’ll...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.